CVE-2020-24240
published 2020-08-25CVE-2020-24240: GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.26%
67.7th percentile
GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bison | < bison 2:3.7.2+dfsg-1 (bookworm) | bison 2:3.7.2+dfsg-1 (bookworm) |
| gnu | bison | — | — |
| gnu | bison | >= 0 < 2:3.7.2+dfsg-1 | 2:3.7.2+dfsg-1 |
| gnu | bison | >= 0 < 2:3.7.2+dfsg-1 | 2:3.7.2+dfsg-1 |
| gnu | bison | >= 0 < 2:3.7.2+dfsg-1 | 2:3.7.2+dfsg-1 |
| gnu | bison | >= 0 < 2:3.7.2+dfsg-1 | 2:3.7.2+dfsg-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5xv5-wxfg-845r: GNU Bison 3
ghsa_unreviewed·2022-05-24
CVE-2020-24240 [HIGH] GHSA-5xv5-wxfg-845r: GNU Bison 3
GNU Bison 3.7 has a use after free (UAF) vulnerability. A local attacker may execute bison with crafted input file containing a NULL byte, which could triggers UAF and thus cause system crash.
OSV
CVE-2020-24240: GNU Bison before 3
osv·2020-08-25·CVSS 5.5
CVE-2020-24240 [MEDIUM] CVE-2020-24240: GNU Bison before 3
GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.
Red Hat
bison: use-after-free via crafted input file containing a NULL byte can lead to DoS
vendor_redhat·2020-07-28·CVSS 5.5
CVE-2020-24240 [MEDIUM] CWE-416 bison: use-after-free via crafted input file containing a NULL byte can lead to DoS
bison: use-after-free via crafted input file containing a NULL byte can lead to DoS
GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.
Statement: bison as shipped in Red Hat Enterprise Linux 7 and 8 does not reproduce this flaw. It properly detects the NULL byte and errors out accordingly instead of causing use-after-free. This is likely due to introduction of vulnerable code in a more recent version of bison.
Pa
Debian
CVE-2020-24240: bison - GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (c...
vendor_debian·2020·CVSS 5.5
CVE-2020-24240 [MEDIUM] CVE-2020-24240: bison - GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (c...
GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.
Scope: local
bookworm: resolved (fixed in 2:3.7.2+dfsg-1)
bullseye: resolved (fixed in 2:3.7.2+dfsg-1)
forky: resolved (fixed in 2:3.7.2+dfsg-1)
sid: resolved (fixed in 2:3.7.2+dfsg-1)
trixie: resolved (fixed in 2:3.7.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-24240 bison: use-after-free via crafted input file containing a NULL byte can lead to DoS [fedora-all]
bugzilla·2020-08-26·CVSS 5.5
CVE-2020-24240 [MEDIUM] CVE-2020-24240 bison: use-after-free via crafted input file containing a NULL byte can lead to DoS [fedora-all]
CVE-2020-24240 bison: use-after-free via crafted input file containing a NULL byte can lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2020-24240 bison: use-after-free via crafted input file containing a NULL byte can lead to DoS
bugzilla·2020-08-26·CVSS 5.5
CVE-2020-24240 [MEDIUM] CVE-2020-24240 bison: use-after-free via crafted input file containing a NULL byte can lead to DoS
CVE-2020-24240 bison: use-after-free via crafted input file containing a NULL byte can lead to DoS
GNU Bison 3.7 has a use after free (UAF) vulnerability. A local attacker may execute bison with crafted input file containing a NULL byte, which could triggers UAF and thus cause system crash.
Reference:
https://lists.gnu.org/r/bug-bison/2020-07/msg00051.html
Upstream patch:
https://github.com/akimd/bison/commit/be95a4fe2951374676efc9454ffee8638faaf68d
Discussion:
Created bison tracking bugs for this issue:
Affects: fedora-all [bug 1872738]
---
Statement:
bison as shipped in Red Hat Enterprise Linux 7 and 8 does not reproduce this flaw. It properly detects the NULL byte and errors out accordingly instead of causing use-after-free. This is likely due to introduction of vulnerable code
https://github.com/akimd/bison/commit/be95a4fe2951374676efc9454ffee8638faaf68dhttps://github.com/akimd/bison/compare/v3.7...v3.7.1https://lists.gnu.org/r/bug-bison/2020-07/msg00051.htmlhttps://github.com/akimd/bison/commit/be95a4fe2951374676efc9454ffee8638faaf68dhttps://github.com/akimd/bison/compare/v3.7...v3.7.1https://lists.gnu.org/r/bug-bison/2020-07/msg00051.html
2020-08-25
Published